HCW8078 Migration Endpoint could not be created. Error details: Access is denied..

Brunno Martins 1 Reputation point
2022-07-18T03:18:51.15+00:00

Hello friends!

I want your help to resolve the error message below when I try to create a migration endpoint in Exchange 2016.

Error received when terminating hybrid Configuration wizard:

HCW8078 Migration Endpoint could not be created.
Microsoft.Exchange.Migration.MigrationServerConnectionFailedException
The connection to the server 'myserver.com' could not be completed. Microsoft.Exchange.MailboxReplicationService.MRSRemoteTransientException
The call to 'https://myserver.com/EWS/mrsproxy.svc' failed. Error details: Access is denied..
Microsoft.Exchange.MailboxReplicationService.MRSRemotePermanentException
Access is denied.

Checks performed:
Opened ports in the firewall;
active MRSproxy;
Permissions set correctly for the EWS directory;
All updates applied on Windows and Exchange;
Admincount set to zero;
MSExchangeServicesAppPool recycled and IIS restarted;
There is no migration endpoint created, so it's not a credential issue;
I did the connectivity test on https://testconnectivity.microsoft.com/ and the result was success without errors.

If anyone has any guesses and can help, I'd be very grateful!
I need to find the light at the end of the tunnel, because this problem is taking my peace.

Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,338 questions
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,461 questions
Microsoft Exchange Hybrid Management
Microsoft Exchange Hybrid Management
Microsoft Exchange: Microsoft messaging and collaboration software.Hybrid Management: Organizing, handling, directing or controlling hybrid deployments.
1,970 questions
{count} votes

3 answers

Sort by: Most helpful
  1. T. Kujala 8,706 Reputation points
    2022-07-18T05:29:03.093+00:00

  2. Amit Singh 4,866 Reputation points
    2022-07-19T11:10:13.09+00:00

    There are a few points which you need to check.

    • Make sure Outlook Anywhere succeeds with the test account.
    • Ensure you enter the credentials with domain\username in all locations while creating the endpoint.
    • Please make sure the internal and External hostname is in the certificate (In a strange case, user ad multi-domain wild card cert where we move internal and external hostname to the primary FQDN of the cert)
    • Make sure HTTP redirect is not set EWS virtual directories.
    • Also, make sure Basic and Windows auth is enabled on EWS virtual directory.

    Also, check joyceshen-MSFT answer in this thread - https://video2.skills-academy.com/en-us/answers/questions/353681/hcw8078-migration-endpoint-could-not-be-created.html


  3. Phil 0 Reputation points
    2024-06-24T08:10:34.1+00:00

    The EXO team has a great blogpost troubleshooting exactly such issues (Access Denied, Timeout, TLS, ...):

    https://techcommunity.microsoft.com/t5/exchange-team-blog/troubleshooting-hybrid-migration-endpoints-in-classic-and-modern/ba-p/953006

    0 comments No comments